JTSTech Services
← All articles

Strategy · September 30, 2026 · 8 min read

Only 7% of people are comfortable giving an AI assistant their data. Most of the rest say yes anyway, and that yes behaves nothing like a real one.

New research published on 29 September puts a number on something most businesses adding AI have never measured: of 11,000 consumers surveyed across seven markets, 7% are fully comfortable granting an AI assistant access to their data with no conditions, while 17% grant it despite being uncomfortable. Reluctant consent outnumbered willing consent by more than two to one in every data category and every generation. The uncomfortable part for anyone shipping AI features is that both groups look identical in your metrics — and in the same dataset, 47% of consumers had already taken an action with a direct revenue consequence over how their data was used in AI.

Written by Jeremy Souffir Founder, JTS Tech Services

The short version, and the direct answer if you read nothing else. Your AI feature's adoption rate is not measuring what you think it is measuring. Research published on 29 September found that of 11,000 consumers surveyed, only 7% were fully comfortable granting an AI assistant access to their data with no conditions attached, while 17% granted that access while actively uncomfortable about it — and that across every data category and every age group tested, reluctant consent outnumbered willing consent by more than two to one. Both kinds of yes arrive in your dashboard as the same event. They do not behave the same way afterwards. In the same body of research, 47% of consumers said they had already taken at least one action with a direct revenue consequence in the previous six months — cancelling, switching, or spending less — because of how a company was using their data in AI. This is not an argument against shipping AI. It is an argument that the adoption number you are reporting upward has a second number hidden inside it, and that the hidden one is the one that predicts what happens next quarter.

Whose numbers these are, and how much weight they should carry

  • The publisher has a commercial interest. Usercentrics sells consent management software. A study finding that consent is fragile and that transparency is commercially valuable is a study that supports what the company sells. That does not make the numbers wrong, and the methodology is disclosed more fully than most vendor research, but you should read it knowing which way the incentive points.
  • The sample is large and the method is stated. 11,000 consumers across seven markets — the UK, the United States, Germany, Spain, Italy, the Netherlands and Sweden — fielded by Sapio Research, with a stated margin of error of plus or minus 0.9% at 95% confidence. That is a serious sample, and larger than most of what gets quoted in this space.
  • The fieldwork is older than the headline. The survey ran in March 2026. The 29 September release is a new analysis of that existing dataset, not new fieldwork. So this is six-month-old sentiment about a subject that moves quickly, and it predates several of the agentic shopping launches we have written about since. Treat the direction as more reliable than the decimal places.
  • Canada was not surveyed. Neither was any market outside Europe and the United States. If you sell into Canada, as most of the businesses we work with do, the closest proxy in the set is the US figure, and that is a proxy rather than a measurement.
  • It measures stated attitudes, not observed behaviour. People report their privacy preferences more strongly than they act on them — the long-documented privacy paradox. The genuinely interesting finding here works with that grain rather than against it: the study is not claiming people refuse. It is claiming they agree, and resent it, and that the resentment is doing something measurable later.

What did the research actually find?

  • Comfort is rare. 7% of respondents were fully comfortable granting an AI assistant access to their data with no conditions. Nearly 60% said they were uncomfortable with it. The gap between those two numbers is where almost all of your users live.
  • Most people who agree are not happy about it. 17% granted access despite being uncomfortable — the pattern the researchers named resigned consent. Across every data category and generation measured, that reluctant yes outnumbered the willing yes by more than two to one.
  • Refusal is common too, and varies by market. The average outright refusal rate was 23%. Germany had both the highest resigned-consent rate at 24% and a lower refusal rate at 16% — people there agree reluctantly more often than they walk away. The UK sat at 11% resigned consent and the US at 10%.
  • The category matters more than the person. Financial account access drew 64% discomfort and only 14% resigned consent, with roughly 24% saying they would abandon the product entirely rather than grant it. Work tools, email and calendar, and health data drew the highest resigned-consent rates at 17%. People do not have one AI privacy setting; they have one per kind of data, and financial data is where reluctance turns into refusal.
  • Age changes the refusal rate, not the reluctance. Roughly a quarter to a third of the people saying yes were reluctant about it in every generation surveyed, Gen Z included. Younger users are not a segment that has made peace with this; they are a segment that agrees more often while feeling the same way.
Two inbound paths that arrive at the same collection point and register as one identical signal. The upper path runs clear and direct into the junction. The lower path, carrying visibly more volume, reaches the same junction through a series of narrow constrictions and reluctant bends, under evident back-pressure. Past the junction the two are merged into a single outgoing channel where nothing distinguishes them, feeding one indicator that reads the combined total. The stress is all upstream, on a section the indicator does not measure.
Two inbound paths that arrive at the same collection point and register as one identical signal. The upper path runs clear and direct into the junction. The lower path, carrying visibly more volume, reaches the same junction through a series of narrow constrictions and reluctant bends, under evident back-pressure. Past the junction the two are merged into a single outgoing channel where nothing distinguishes them, feeding one indicator that reads the combined total. The stress is all upstream, on a section the indicator does not measure.

Why does a reluctant yes behave differently from a real one?

Because consent is not the end of the interaction, it is the beginning of one, and the two kinds of yes have different amounts of tolerance stored behind them. A willing yes is a small deposit of trust: when something goes slightly wrong — an odd recommendation, a data breach at a company the customer has barely heard of, a news cycle about a model trained on something it should not have been — that deposit absorbs it. A resigned yes has no deposit. It was given because the alternative was not using the product, or because the dialog would not go away, and it is already sitting at the edge of the customer's tolerance on the day it is given. The head of the research team at Usercentrics put the consequence more sharply than we would have: "A resigned yes and a real one look identical in your consent rate, but behave nothing alike." The practical version for anyone running a business is that your consent rate is a lagging indicator dressed as a leading one. It tells you what people did at the dialog. It tells you nothing about how much of that agreement would survive a bad week.

A resigned yes and a real one look identical in your consent rate, but behave nothing alike.

And unlike most soft trust findings, this one has a hard number attached in the same dataset. 47% of respondents had taken at least one action with a direct revenue consequence in the previous six months over how their data was being used in AI; 35% had taken two or more. The specific actions break down as 24% who avoided trying a new product, 20% who switched to a competitor, 20% who reduced their spending, and 31% who warned friends and family or complained publicly. Those are not attitudes. Those are churn, lost acquisition, reduced basket size and negative word of mouth, and every one of them shows up in a business's numbers attributed to something else entirely — a pricing problem, a competitor's campaign, a soft quarter. Nobody cancels a subscription and writes "your AI disclosure was vague" in the reason box.

The two conclusions that both get this wrong

The first is to read 60% discomfort as a reason to slow down on AI, or to quietly stop mentioning it. This is the wrong lesson and the research contradicts it directly: in the same survey, daily AI use kept climbing while comfort did not. People are using these tools regardless, including your customers, including the ones who told a surveyor they were uncomfortable. A business that responds by removing AI from its roadmap loses the capability and keeps the trust problem, because its competitors' AI features are still the ones training the customer's expectations. Worse is the version where the feature ships and the disclosure gets softened until it says nothing — that is not a lower-risk position, it is the same position with the evidence removed. The second conclusion is the more sophisticated-sounding one and it is just as wrong: that this is a compliance matter, and therefore already handled because somebody reviewed the privacy policy against the EU AI Act transparency obligations that came into force in August. Compliance sets the floor for what you are permitted to do. It has almost nothing to say about whether a customer feels good about it, and the 47% who acted were not consulting your legal basis when they did. A consent flow can be entirely lawful, fully documented, approved by counsel, and still be manufacturing resigned yeses at scale — in fact a well-drafted one is often better at it, because legal review optimises for defensibility rather than for the customer understanding what they agreed to. Neither conclusion is lazy, which is exactly why both are common: one treats a trust problem as a product problem, the other treats it as a paperwork problem, and the actual work sits between them where no single department owns it.

The same structural load carried two ways. On the left, a platform rests on a dense field of short, thick, evenly seated columns, each one bearing a small share and the whole assembly sitting square. On the right, an identical platform at an identical height is held up by a sparse row of tall, thin, visibly strained supports, several already bowing under the weight. Viewed from directly above, as the single indicator dial beside them views it, the two platforms are at exactly the same level and read as equal. The difference only appears in profile, and only matters when something is added on top.
The same structural load carried two ways. On the left, a platform rests on a dense field of short, thick, evenly seated columns, each one bearing a small share and the whole assembly sitting square. On the right, an identical platform at an identical height is held up by a sparse row of tall, thin, visibly strained supports, several already bowing under the weight. Viewed from directly above, as the single indicator dial beside them views it, the two platforms are at exactly the same level and read as equal. The difference only appears in profile, and only matters when something is added on top.

What does this change for a business shipping AI right now?

  • Stop treating the consent rate as a health metric. It is a volume metric. If you want to know whether the agreement is real, you have to look at what happens after it: do people who enabled the AI feature use it a second time, do they turn it back off, do they complete the flow that the AI touched at a different rate than the flow it does not. Those are all measurable this quarter with data you already have, and none of them is on the dashboard the feature launched with.
  • Be specific about data categories rather than asking once about AI. The research is clear that people price access by category, and that financial data is close to a hard boundary — 64% uncomfortable, and roughly a quarter who would abandon the product rather than grant it. A single blanket AI permission asks your most cautious customers to make their most uncomfortable decision at the same moment as their most trivial one, and they will resolve that by refusing the lot. Asking separately, at the point each one is needed, costs you an engineering afternoon and is the single highest-leverage change on this list.
  • Say what the AI does in words a customer would use. Most AI disclosure we read is written to satisfy a reviewer: accurate, complete, and entirely unreadable. The test is not whether it is defensible, it is whether a customer who read it could correctly answer what data leaves, where it goes, and whether it trains anything. If your own team cannot answer that from your own disclosure, your customers are consenting to a blank.
  • Find out whether your disclosure is still true. This is the one that catches people. Disclosures are written at launch and systems change afterwards — a model swap, a new subprocessor, an agent that gained access to a system it did not have before, a vendor that turned an AI feature on for you by default. We have written repeatedly this year about capabilities that arrived switched on. Every one of those is a potential gap between what your privacy page says and what your stack does, and that gap is the thing that turns a resigned yes into a public complaint.
  • Expect this to get harder to ignore, not easier. Separately in the same research, 48% of consumers reported clicking "accept all" on cookies less often than they did three years ago, up from 46% the year before. The direction of travel on blanket consent has been one way for a decade, and the AI-specific version is starting from a much lower base of comfort than cookies ever did.
  • Do not commission a survey of your own customers to confirm this. It is a tempting and expensive way to spend six weeks arriving at the same answer. The behavioural evidence you need is already in your product analytics and your cancellation reasons, and reading those is a week's work.

The genuinely encouraging part

There is an upside number in this research and it is larger than the risk number. 52% of consumers said they would pay more for brands that are transparent about how they use AI, at an average premium of 7%. In Germany that rose to 73% of consumers at a 9% premium; in the US, half of consumers, and even in the lowest markets it did not fall below about a third. Read that next to the 47% who had already acted against a company over AI data use and the shape of the opportunity is unusually clean: the same customers who will punish opacity will pay for clarity, and clarity is cheap. It does not require a model, a vendor, a platform migration or a budget line. It requires knowing what your systems actually do with customer data and being willing to write it down in plain language — and if you cannot currently produce that document, the effort of producing it is worth doing for its own sake, because the questions it forces are the ones nobody has asked out loud. This is also, unusually for this subject, work that compounds in the right direction. Nearly every AI trend we have covered on this blog this year has raised the floor on what businesses have to do to stay visible or stay safe. This is the rare one that rewards you for something rather than penalising you for its absence, and it rewards the businesses small enough to actually know what their systems do — which is to say, most of the ones reading this, and almost none of their largest competitors.

Where we fit

The work this research implies is awkward precisely because it is not a build. There is no feature to ship, no integration to stand up and no vendor to evaluate, which means it does not enter a backlog and does not get a sprint. It is a set of decisions — which AI capabilities the business is prepared to run, what data each one genuinely needs, what customers are told and in whose words, and who signs off when any of that changes — and those decisions currently sit unevenly across marketing, legal, engineering and whoever originally turned the feature on. The failure mode is not that anybody gets it wrong. It is that four people each hold a defensible piece and no one holds the whole picture, so the privacy page drifts away from the systems quietly, over months, and nobody discovers the gap until a customer does. That is the shape of problem the Fractional Head of AI & Digital engagement exists for: senior AI leadership inside the business a day or two a week, long enough to inventory what is actually running and what data each thing touches, decide what the business's position is and write it down in language a customer could read, put a named owner on each AI capability and on the disclosure that covers it, and set the review cadence that catches the drift the next time a vendor switches something on. Retaining us for this matters for one specific reason: the cost here is entirely invisible until it is large. A resigned yes does not generate a support ticket, an error or an alert — it generates a customer who is slightly less likely to come back, and that shows up in a churn number next year attributed to price. Somebody has to own the question before there is an incident to own it after, and that person needs enough seniority to say no to a capability, which is not a position an agency delivering a project can occupy.

Sources

Keep reading

Fractional Head of AI & Digital

Could you write down, today, what every AI system in your business does with customer data?

We inventory the AI capabilities actually running across your business and the data each one touches, find where your privacy page has drifted away from what your systems now do, put a named owner on every capability and on the disclosure that covers it, rewrite that disclosure in language a customer could actually read, and set the review cadence that catches it the next time a vendor switches something on by default.